CrowdStrike: AI as a Weapon and Target of Cyberattacks

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
AI: A Double-Edged Sword for Cybersecurity
Artificial intelligence (AI) is now seen as a dual-use tool in the field of cybersecurity: it is both a powerful weapon for cybercriminals and a prime target for their attacks. This duality forces companies to rethink their defense strategies to face increasingly sophisticated and difficult-to-manage threats.
According to the recent 2026 Threat Hunting Report from CrowdStrike, published this Monday, the same AI technologies that promise to enhance business productivity are also being exploited by cybercriminals on a large scale. These criminals use these tools to conduct more effective and faster attacks.
With the continued expansion of enterprise networks, the addition of endpoint devices, and the deployment of new large language models (LLMs), organizations are inadvertently creating larger attack surfaces. These surfaces can be exploited to steal data, access AI models, conduct surveillance operations, and even hijack computing resources for malicious purposes.
AI: A Weapon and a Target
Adam Meyers, head of threat intelligence at CrowdStrike, emphasizes that AI is not just a tool or a weapon, but also an attack surface in itself. Malicious actors are adopting AI as quickly as businesses, complicating the task for defenders.
The report indicates that the massive adoption of AI, often new and untested, significantly increases the volume of signals that security teams must analyze. There are now 2.5 times more trails generated by AI agents than by manual methods, making it harder to distinguish between malicious activity and normal AI-driven behavior.
Alerts and suspicious signals highlight the use of AI in the criminal world, where attacks are carried out at an impressive speed. CrowdStrike cites several examples:
-
Famous Chollima: This group, linked to North Korea, uses trusted AI environments and tools to target cryptocurrency and blockchain companies, employing AI-generated resumes and deepfake interviews.
-
Cordial Spider and Snarky Spider: These groups use vishing to extract data from SaaS applications and compromise single sign-on accounts. A documented attack transitioned from account takeover to data theft in less than five minutes.
-
LLMJacking: This term refers to unauthorized access to keys or credentials that allow access to a company's AI models. Cybercriminals can then steal data or force the model to execute costly tasks, leading to high bills for the victim. For instance, one campaign used the victim's LLM to generate nearly 200,000 API requests in two minutes, causing significant financial and operational impact.
Reducing Vulnerability Windows
The report also highlights a concerning trend: the shrinking time defenders have to react between the discovery of a vulnerability and its exploitation. From January to June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of the publication of a proof-of-concept (PoC) code.
Certain threat groups, such as Vault Panda and Genesis Panda from China, closely monitor new vulnerabilities. They developed functional exploits for a critical vulnerability in a web application (React2Shell) in just 24 hours after its disclosure.
In these cases, AI plays a crucial role. Two recently discovered exploits, CopyFail and Fragnesia (with Dirty Frag as a third), were identified through AI-assisted research. The report notes that cybercriminals quickly integrated them into their operations.
Implications for Businesses and Their Cybersecurity Teams
CrowdStrike warns that response times will continue to shorten, largely due to the weaponization of AI. Researchers believe that the implementation of advanced AI systems could accelerate the discovery of vulnerabilities and the development of exploits, thereby increasing pressure on already overwhelmed defenders.
Recommended Actions
While AI can act as a shield, it can also be used as a weapon, as shown by CrowdStrike's research. In the face of growing pressure from AI, defenders must double their efforts to secure networks and endpoints.
CrowdStrike recommends that companies adopt the following practices:
-
Secure AI Applications and LLMs: With AI integrated into many enterprise environments, it is crucial to apply least privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to mitigate risks.
-
Identity as the Primary Attack Surface: Although this issue predates AI, securing and verifying identities is now more important than ever. Organizations must implement phishing-resistant multifactor authentication, monitor access to enterprise resources, and apply least privilege to both human and non-human accounts.
-
Address Cross-Domain Blind Spots and Secure the Software Supply Chain: Digital blind spots in the supply chain and within networks can be exploited. Telemetry, behavioral detection, and analytics software, along with frequent patch cycles and threat intelligence, can reduce the risk of compromise.
-
Adopt a Proactive Approach: The weaponization of AI, moving at a speed we cannot keep up with, forces organizations to shift from a reactive security posture to a proactive one. Investment, threat triage, and resolution of legacy security issues must be addressed swiftly to reduce the attack surface and give teams the space needed to keep pace.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.